aboutsummaryrefslogtreecommitdiff
path: root/tests/cfgs
diff options
context:
space:
mode:
authorNardi Ivan <nardi.ivan@gmail.com>2023-06-01 08:05:41 +0200
committerIvan Nardi <12729895+IvanNardi@users.noreply.github.com>2023-06-08 17:07:25 +0200
commitfd4cb10190f00ab4a114c26c95f7fe6e1cb5056b (patch)
tree5da8e91bce75ece26f099d0feee4577449bcd4ea /tests/cfgs
parent9987e5b4822cb55d597eb4bbe3c199df99d453b9 (diff)
QUIC: add support for QUIC version 2
See: https://www.rfc-editor.org/rfc/rfc9369.txt Old v2-01 version has been removed, since it has never been really used.
Diffstat (limited to 'tests/cfgs')
-rw-r--r--tests/cfgs/default/pcap/quic-v2-01.pcapngbin10844 -> 0 bytes
-rw-r--r--tests/cfgs/default/pcap/quic-v2.pcapngbin0 -> 24800 bytes
-rw-r--r--tests/cfgs/default/result/quic-v2-01.pcapng.out30
-rw-r--r--tests/cfgs/default/result/quic-v2.pcapng.out30
4 files changed, 30 insertions, 30 deletions
diff --git a/tests/cfgs/default/pcap/quic-v2-01.pcapng b/tests/cfgs/default/pcap/quic-v2-01.pcapng
deleted file mode 100644
index 583986db7..000000000
--- a/tests/cfgs/default/pcap/quic-v2-01.pcapng
+++ /dev/null
Binary files differ
diff --git a/tests/cfgs/default/pcap/quic-v2.pcapng b/tests/cfgs/default/pcap/quic-v2.pcapng
new file mode 100644
index 000000000..bb472a44e
--- /dev/null
+++ b/tests/cfgs/default/pcap/quic-v2.pcapng
Binary files differ
diff --git a/tests/cfgs/default/result/quic-v2-01.pcapng.out b/tests/cfgs/default/result/quic-v2-01.pcapng.out
deleted file mode 100644
index 665824df3..000000000
--- a/tests/cfgs/default/result/quic-v2-01.pcapng.out
+++ /dev/null
@@ -1,30 +0,0 @@
-Guessed flow protos: 0
-
-DPI Packets (UDP): 1 (1.00 pkts/flow)
-Confidence DPI : 1 (flows)
-Num dissector calls: 61 (61.00 diss/flow)
-LRU cache ookla: 0/0/0 (insert/search/found)
-LRU cache bittorrent: 0/0/0 (insert/search/found)
-LRU cache zoom: 0/0/0 (insert/search/found)
-LRU cache stun: 0/0/0 (insert/search/found)
-LRU cache tls_cert: 0/0/0 (insert/search/found)
-LRU cache mining: 0/0/0 (insert/search/found)
-LRU cache msteams: 0/0/0 (insert/search/found)
-LRU cache stun_zoom: 0/0/0 (insert/search/found)
-Automa host: 0/0 (search/found)
-Automa domain: 0/0 (search/found)
-Automa tls cert: 0/0 (search/found)
-Automa risk mask: 0/0 (search/found)
-Automa common alpns: 18/18 (search/found)
-Patricia risk mask: 2/0 (search/found)
-Patricia risk: 0/0 (search/found)
-Patricia protocols: 2/0 (search/found)
-
-QUIC 10 7663 1
-
-JA3 Host Stats:
- IP Address # JA3C
- 1 192.168.56.1 1
-
-
- 1 UDP 192.168.56.1:34229 <-> 192.168.56.198:4443 [proto: 188/QUIC][IP: 0/Unknown][Encrypted][Confidence: DPI][DPI packets: 1][cat: Web/5][5 pkts/3543 bytes <-> 5 pkts/4120 bytes][Goodput ratio: 94/95][0.00 sec][(Advertised) ALPNs: h3-34;hq-34;h3-33;hq-33;h3-32;hq-32;h3-31;hq-31;h3-29;hq-29;h3-30;hq-30;h3-28;hq-28;h3-27;hq-27;h3;hq-interop][TLS Supported Versions: TLSv1.3;TLSv1.3 (draft);TLSv1.3 (draft);TLSv1.3 (draft)][bytes ratio: -0.075 (Mixed)][IAT c2s/s2c min/avg/max/stddev: 0/0 0/0 2/0 1/0][Pkt Len c2s/s2c min/avg/max/stddev: 97/97 709/824 1482/1482 569/511][Risk: ** Known Proto on Non Std Port **** Missing SNI TLS Extn **][Risk Score: 100][Risk Info: No server to client traffic][TLSv1.3][JA3C: c0ce40fbb78cbf86a14e6a38b26d6ede][Plen Bins: 0,20,0,0,0,10,0,0,0,0,0,0,10,10,0,0,0,0,0,0,0,0,10,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,20,0,0,0,0,0,20,0,0]
diff --git a/tests/cfgs/default/result/quic-v2.pcapng.out b/tests/cfgs/default/result/quic-v2.pcapng.out
new file mode 100644
index 000000000..5a25039f8
--- /dev/null
+++ b/tests/cfgs/default/result/quic-v2.pcapng.out
@@ -0,0 +1,30 @@
+Guessed flow protos: 0
+
+DPI Packets (UDP): 1 (1.00 pkts/flow)
+Confidence DPI : 1 (flows)
+Num dissector calls: 59 (59.00 diss/flow)
+LRU cache ookla: 0/0/0 (insert/search/found)
+LRU cache bittorrent: 0/0/0 (insert/search/found)
+LRU cache zoom: 0/0/0 (insert/search/found)
+LRU cache stun: 0/0/0 (insert/search/found)
+LRU cache tls_cert: 0/0/0 (insert/search/found)
+LRU cache mining: 0/0/0 (insert/search/found)
+LRU cache msteams: 0/0/0 (insert/search/found)
+LRU cache stun_zoom: 0/0/0 (insert/search/found)
+Automa host: 1/0 (search/found)
+Automa domain: 1/0 (search/found)
+Automa tls cert: 0/0 (search/found)
+Automa risk mask: 1/0 (search/found)
+Automa common alpns: 1/1 (search/found)
+Patricia risk mask: 0/0 (search/found)
+Patricia risk: 0/0 (search/found)
+Patricia protocols: 0/0 (search/found)
+
+QUIC 19 12970 1
+
+JA3 Host Stats:
+ IP Address # JA3C
+ 1 ::1 1
+
+
+ 1 UDP [::1]:42086 <-> [::1]:4443 [proto: 188/QUIC][IP: 0/Unknown][Encrypted][Confidence: DPI][DPI packets: 1][cat: Web/5][8 pkts/2734 bytes <-> 11 pkts/10236 bytes][Goodput ratio: 81/93][0.54 sec][Hostname/SNI: test][(Advertised) ALPNs: h3][TLS Supported Versions: TLSv1.3][bytes ratio: -0.578 (Download)][IAT c2s/s2c min/avg/max/stddev: 0/0 90/44 251/100 114/43][Pkt Len c2s/s2c min/avg/max/stddev: 119/119 342/931 1296/2098 370/669][Risk: ** Known Proto on Non Std Port **][Risk Score: 50][Risk Info: No server to client traffic][TLSv1.3][JA3C: 5e685944fc983af5eabcc813add3dca1][Plen Bins: 0,26,0,0,5,15,0,0,0,5,0,0,0,10,0,0,0,5,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,5,0,0,0,0,0,0,21,0,5]